This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack Log Inside Need Lots Of Help

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the whole log I have lots of problems with spyware that doesn't go away. I could copy paste one of my spy sweeper scans if you want.


Logfile of HijackThis v1.98.2
Scan saved at 9:39:42 PM, on 10/8/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\appww32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TiqTL219.exe
C:\WINDOWS\system32\Azk4OX3T.exe
C:\WINDOWS\Q308387Uninst.log:pvmbo
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MOZILLA.ORG\MOZILLA\MOZILLA.EXE
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {4604FEF0-A46F-3D1C-FBB2-34257F010E20} - C:\WINDOWS\system32\creo32.dll
O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\system32\Upwt.exe
O4 - HKLM\..\Run: [sdkiq.exe] C:\WINDOWS\system32\sdkiq.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [mska32.exe] C:\WINDOWS\system32\mska32.exe
O4 - HKLM\..\Run: [ieyq32.exe] C:\WINDOWS\system32\ieyq32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mfcrj32.exe] C:\WINDOWS\system32\mfcrj32.exe
O4 - HKLM\..\Run: [mfcnu32.exe] C:\WINDOWS\system32\mfcnu32.exe
O4 - HKLM\..\Run: [msuk32.exe] C:\WINDOWS\system32\msuk32.exe
O4 - HKLM\..\Run: [iedz32.exe] C:\WINDOWS\system32\iedz32.exe
O4 - HKLM\..\Run: [crli32.exe] C:\WINDOWS\system32\crli32.exe
O4 - HKLM\..\Run: [appbq32.exe] C:\WINDOWS\system32\appbq32.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [appww32.exe] C:\WINDOWS\appww32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
Welcome to the forum.

Are you sure that's the whole log, seems to be missing entries 05 - 018 or more. Please check.

The key to fixing this hijacker is posting a fresh HJT log and not turning off or rebooting the computer until we are finished with procedure.

I need you to download and install these programs: (don't run or use them yet!!)

Download AboutBuster

Please download and install AD-Aware.
Check Here on how setup and use it - please make sure you update it first.

Click here http://www.davehigham.zen.co.uk/downloads/cwsuninst.zip to download cwsuninst.zip.
Extract cwsuninst.reg from the zip file and save it to the desktop.

Download the Hoster from here http://members.aol.com/toadbee/hoster.zip.

Download CW-Shredder

Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

For anyone using Windows XP, 'Search' will not automatically show hidden files even if your folder options settings are set to do that. Do this so you can see hidden files and folders - click here http://www.davehigham.zen.co.uk/downloads/xphidden.zip to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes.


If you can do those for me including posting a fresh complete HJT log , I'll get back to you ASAP with the procedure to fix this hijacker. MrC
Ok I have Adware already installed so I updated it today. Downloaded and installed all the things you told me to I still havn't used any of them yet. I checked the things you told me to in explorer. For the Hijack log thats all there is.


Logfile of HijackThis v1.98.2
Scan saved at 12:20:50 PM, on 10/9/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\appww32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Q308387Uninst.log:pvmbo
C:\WINDOWS\system32\TiqTL219.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\CnbP.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {4604FEF0-A46F-3D1C-FBB2-34257F010E20} - C:\WINDOWS\system32\creo32.dll
O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\System32\Fsm6BY.exe
O4 - HKLM\..\Run: [sdkiq.exe] C:\WINDOWS\system32\sdkiq.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [mska32.exe] C:\WINDOWS\system32\mska32.exe
O4 - HKLM\..\Run: [ieyq32.exe] C:\WINDOWS\system32\ieyq32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mfcrj32.exe] C:\WINDOWS\system32\mfcrj32.exe
O4 - HKLM\..\Run: [mfcnu32.exe] C:\WINDOWS\system32\mfcnu32.exe
O4 - HKLM\..\Run: [msuk32.exe] C:\WINDOWS\system32\msuk32.exe
O4 - HKLM\..\Run: [iedz32.exe] C:\WINDOWS\system32\iedz32.exe
O4 - HKLM\..\Run: [crli32.exe] C:\WINDOWS\system32\crli32.exe
O4 - HKLM\..\Run: [appbq32.exe] C:\WINDOWS\system32\appbq32.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [appww32.exe] C:\WINDOWS\appww32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
Good, I hope you haven't turn your computer off since that log you posted, if you did, there's a good chance the files names have changed.

Do one more thing: Peper Fix

Download PeperFix.exe , don't run it yet.

Now disconnect from the net until you run the virus scan.

Please read through and follow the instructions carefully before you start (you may want to print this out).


Important Step
Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called: (you may find one or more)

Network Security Service <—this is exactly what they look like
Remote Procedure Call (RPC) Helper <—
or
Workstation NetLogon Service
<—

There are two other RPC services that should be left alone.

Here's an example of what it may look like:

The BINARY_PATH_NAME = "the bad file (make note of it)" <——–
The Display name = "the service" <————-

============================================================
Example
SERVICE_NAME: O?-’ŽrtñåȲ$Ó
(null)
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\Greenstone.bmp:pcsbq /s<————
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Remote Procedure Call (RPC) Helper <——-
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

=====================================================================

1. When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.


2. Press Ctrl+Alt+Delete once => Click Task Manager => Click the Processes tab => Double-click the Image Name column header to alphabetically sort the processes => Scroll through the list and look for:

the bad file (from the service)
Fsm6BY.exe
sdkiq.exe
mska32.exe
ieyq32.exe
mfcrj32.exe
mfcnu32.exe
msuk32.exe
iedz32.exe
crli32.exe
appbq32.exeO4
appww32.exe

If you find the files, click on them, and then click End Process => Exit the Task Manager.



3. CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qvvsd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qvvsd.dll/sp.html#37049

O2 - BHO: (no name) - {4604FEF0-A46F-3D1C-FBB2-34257F010E20} - C:\WINDOWS\system32\creo32.dll

O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\System32\Fsm6BY.exe
O4 - HKLM\..\Run: [sdkiq.exe] C:\WINDOWS\system32\sdkiq.exe
O4 - HKLM\..\Run: [mska32.exe] C:\WINDOWS\system32\mska32.exe
O4 - HKLM\..\Run: [ieyq32.exe] C:\WINDOWS\system32\ieyq32.exe
O4 - HKLM\..\Run: [mfcrj32.exe] C:\WINDOWS\system32\mfcrj32.exe
O4 - HKLM\..\Run: [mfcnu32.exe] C:\WINDOWS\system32\mfcnu32.exe
O4 - HKLM\..\Run: [msuk32.exe] C:\WINDOWS\system32\msuk32.exe
O4 - HKLM\..\Run: [iedz32.exe] C:\WINDOWS\system32\iedz32.exe
O4 - HKLM\..\Run: [crli32.exe] C:\WINDOWS\system32\crli32.exe
O4 - HKLM\..\Run: [appbq32.exe] C:\WINDOWS\system32\appbq32.exe
O4 - HKLM\..\Run: [appww32.exe] C:\WINDOWS\appww32.exe




4. Delete the following files if present:
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.

the bad file <—–from the service above
C:\WINDOWS\qvvsd.dll <—typical
C:\WINDOWS\appww32.exe
C:\WINDOWS\system32\creo32.dll
C:\WINDOWS\System32\Fsm6BY.exe
C:\WINDOWS\system32\sdkiq.exe
C:\WINDOWS\system32\mska32.exe
C:\WINDOWS\system32\ieyq32.exe
C:\WINDOWS\system32\mfcrj32.exe
C:\WINDOWS\system32\mfcnu32.exe
C:\WINDOWS\system32\msuk32.exe
C:\WINDOWS\system32\iedz32.exe
C:\WINDOWS\system32\crli32.exe
C:\WINDOWS\system32\appbq32.exeO4


(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - appsw.exe, appsw.dll, appsw.dat)

5. Run AboutBuster . (run it twice) This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

6. Run the Peper fix:
Start it and click Find and Fix.

7. Scan with AdAware and let it remove any bad files found.

8. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

9. Double-click the cwsuninst.reg and when asked to merge say yes.

10. Run Hoster, Press "Restore Original Hosts" and press "OK". Exit Program.

11. Download and run this online virus scan:
http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure you check "AutoClean"

12. Run the Shredder:
Hit the fix button and let it run and fix what it finds, make sure you have all browser windows closed.

13. Reboot and run the Peper Fix again.

14. Reboot and post a fresh HJT log back here by using the add reply button below, MrC
I did all of the above but I didn't find these files any where what was I using to find these files?
C:\WINDOWS\system32\creo32.dll
C:\WINDOWS\System32\Fsm6BY.exe
C:\WINDOWS\system32\sdkiq.exe
C:\WINDOWS\system32\mska32.exe
C:\WINDOWS\system32\ieyq32.exe
C:\WINDOWS\system32\mfcrj32.exe
C:\WINDOWS\system32\mfcnu32.exe
C:\WINDOWS\system32\msuk32.exe
C:\WINDOWS\system32\iedz32.exe
C:\WINDOWS\system32\crli32.exe
C:\WINDOWS\system32\appbq32.exeO4

I couldn't get cwsuninst.reg to work?

I couldn't get house call to work?

Logfile of HijackThis v1.98.2
Scan saved at 9:12:31 PM, on 10/9/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\netkw32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\ATI Multimedia\main\LaunchPd.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Q308387Uninst.log:pvmbo
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {172A767E-22AD-09EE-8C96-720970A7FA45} - C:\WINDOWS\system32\crqw32.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\system32\Upwt.exe
O4 - HKLM\..\Run: [netkw32.exe] C:\WINDOWS\netkw32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"



Here is the about buster scan

Scan 1 —————————
About:Buster Version 3.0
Reference List : 15

No ADS found on system
Removed 5 Random Key Entries
Deleted 1 Service Keys Successfully!
Removed! : C:\WINDOWS\tpsyn.dat
Removed! : C:\WINDOWS\system32\bpitl.dat
Removed! : C:\WINDOWS\system32\muuyr.dat
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

I still have a Hijacker from about.com, Adware used to detect it but couldn't remove it. Spy sweeper says the hijacker wants to change my home page every time I use internet explorer thats why i'm now using mozila.

I really appreciate the help thus far thanks.
Hello mnster,

I will be taking over from MrCharlie to help you. You have one of the most severe types of infections we are seeing these days and it will take a bit of time to solve your problems. Please follow the steps in order and we'll see if we can get you cleaned up. It may take a few posts to do this. I need to determine what infections you still have on your computer so will ask you to do the following:

Step#1

Please download and open the following zip file. Double-click on the file inside the zip and when it asks you if you would like to merge the file into your registry, please answer yes. This will make sure all files are visible on your computer.

http://www.davehigham.zen.co.uk/downloads/xphidden.zip


Step#2

Please disable SpySweeper as it will prevent the fixes from working. Any protective programs/tools need to be disabled other than your Firewall and AV software, because they prevent the fixes from working properly with the protection they add.


Step#3

I also note that your copy of HijackThis is running from a zip file. It needs to be extracted to its own folder so that it will make backups of the changes we make in case there is a problem with the changes.


Step#4

I need you to download the file from here:

Getservice.zip

Extract the file to the c:\ drive. Then navigate to the c:\getservices and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad as a reply to this post.



Step#5

This infection at times continues to reinstall itself through a hidden dll which we have to find and remove.

1. Please download DllCompare
( The Screenshot will show you how the program will look when it starts.)

2. Start the Program with its default settings and put a check mark in the include subdirectories. Click the Run Locate.com and wait until the scan says complete.

3. Click the Compare button to start the next process.

4. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

5. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan screenshot.

6. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files) screenshot

7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply to receive further instructions.


Step#6

Please post the two log files from the above programs here in this thread.
Since this topic has been inactive for 21 days, I am closing it.

If you need it reopened, please send an email to the following (Click for address) with the Subject line of the email "Reopen".


To receive a response, please include in your email: your post user name, details of why you need it reopened, and a valid link to your post.

Emails with bad links to the post, emails that are not from the original poster, and emails that do not have "ReOpen" as the subject line, will be deleted without being opening.

Please start a New Topic if this is not your thread. Thank-you for your co-operation.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI